VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
2026-05-14 • Hybrid Analysis •
https://hybrid-analysis.blogspot.com/2026/05/velvet-chollima-infostealer-campaign.html
Hybrid Analysis identified a VELVET CHOLLIMA-assessed infostealer operation distributing a signed Windows MSI that masquerades as the Tralert FX cryptocurrency trading application. The installer exposed live credentials and GitLab access tokens, revealing a multi-stage loader chain that uses GitLab repositories for payload delivery, scheduled-task persistence, and recurring exfiltration. The malware collects host reconnaissance, keylogs, and Chromium browser credentials, then pushes stolen data into GitLab repositories every 30 minutes for human triage of cryptocurrency-focused victims. The final payload is MoonPeak, a custom XenoRAT variant, with infrastructure including Tralert/Talert lure domains, GitLab projects, C2 hosts, mutexes, hashes, and the hardcoded C2 IP 91.107.246.107. The campaign matters because the exposed repositories showed active compromise, more than 4,100 commits, roughly 90 affected hosts, and an operational focus on crypto account takeover.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2026-05-14 | 2026-05-14 | |
| [email protected] | 2026-05-14 | 2026-05-14 | |
| [email protected] | 2026-05-14 | 2026-05-14 | |
| [email protected] | 2026-05-14 | 2026-05-14 | |
| URL | https://github.com/Fujinuma0804… | 2026-05-14 | 2026-05-14 |
| URL | https://github.com/vergiegpham/… | 2026-05-14 | 2026-05-14 |
| URL | http://161.97.113.34:3001/api/t… | 2026-05-14 | 2026-05-14 |
| DOMAIN | endava.online | 2026-05-14 | 2026-05-14 |
| DOMAIN | talert.space | 2026-05-14 | 2026-05-14 |
| DOMAIN | talert.online | 2026-05-14 | 2026-05-14 |
| DOMAIN | talert.store | 2026-05-14 | 2026-05-14 |
| DOMAIN | talert.site | 2026-05-14 | 2026-05-14 |
| DOMAIN | tralert.store | 2026-05-14 | 2026-05-14 |
| DOMAIN | tralert.site | 2026-05-14 | 2026-05-14 |
| DOMAIN | trumpalert.store | 2026-05-14 | 2026-05-14 |
| DOMAIN | tralert7.com | 2026-05-14 | 2026-05-14 |
| DOMAIN | tralert.online | 2026-05-14 | 2026-05-14 |
| IPv4 | 91.107.246.107 | 2026-05-14 | 2026-05-14 |
| IPv4 | 161.97.113.34 | 2026-05-14 | 2026-05-14 |
| HASH | 8bcfedccf028a08dafd34a01b036799f | 2026-05-14 | 2026-05-14 |
| HASH | 4794c3cca9a860c8500f51d430cf2392 | 2026-05-14 | 2026-05-14 |
| HASH | 666da559f02a9b217a4c826b17923c0c | 2026-05-14 | 2026-05-14 |
| HASH | f10d35fedb6aa986cef4c113edfdef26 | 2026-05-14 | 2026-05-14 |